CVE-2024-43812: Kieback&peter DDC4002
High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Kieback & Peter's DDC4000 series has an insufficiently protected credentials vulnerability, which may allow an unauthenticated attacker with access to /etc/passwd to read the password hashes of all users on the system.
Affected products
- Kieback&peter DDC4002: up to and including 1.12.14
- Kieback&peter DDC4002E: up to and including 1.17.6
- Kieback&peter DDC4020E: up to and including 1.17.6
- Kieback&peter DDC4040E: up to and including 1.17.6
- Kieback&peter DDC4100: up to and including 1.7.4
- Kieback&peter DDC4200: up to and including 1.12.14
- Kieback&peter DDC4200-L: up to and including 1.12.14
- Kieback&peter DDC4200E: up to and including 1.17.6
- Kieback&peter DDC4400: up to and including 1.12.14
- Kieback&peter DDC4400E: up to and including 1.17.6
- Kieback\&peter DDC4002 Firmware: up to and including 1.12.14
- Kieback\&peter DDC4002E Firmware: up to and including 1.17.6
- Kieback\&peter DDC4020E Firmware: up to and including 1.17.6
- Kieback\&peter DDC4040E Firmware: up to and including 1.17.6
- Kieback\&peter DDC4100 Firmware: up to and including 1.7.4
- Kieback\&peter DDC4200-L Firmware: up to and including 1.12.14
- Kieback\&peter DDC4200 Firmware: up to and including 1.12.14
- Kieback\&peter DDC4200E Firmware: up to and including 1.17.6
- Kieback\&peter DDC4400 Firmware: up to and including 1.12.14
- Kieback\&peter DDC4400E Firmware: up to and including 1.17.6
Published 2024-10-22. Last modified 2026-06-17.